Hi,

why manifest signatures are still optional for repoman?

Repoman signatures are currently optional and this creates nasty
consequences: if signing errors occurs, repoman still proceeds :/

I just had a phone call during repoman commit and was not able to
type my password. Due to gpg-agent timeout repoman completed commit
without a signature :( Should signatures be mandatory, repoman will
bail out on such conditions and devs can recommit again safely.

Best regards,
Andrew Savchenko

Attachment: pgpMPfsW7sZ2V.pgp
Description: PGP signature

Reply via email to